Continuous vs. point-in-time: why an annual pentest is a photograph, not a film
Most companies buy security testing the way you’d commission a portrait: once a year, book a professional, get a polished artefact, file it, repeat next year. It feels responsible. There is a report in the drawer with your name on it and a lot of expensive-looking findings, most of them fixed.
Here is the uncomfortable part. A penetration test is a photograph. It is an accurate, high-resolution picture of your exposure on the day it was taken. The problem is that your attack surface is not a still life. It is a film, and it keeps playing after the photographer goes home.
What changes between reports
Your external estate - everything you expose to the internet - is not a fixed thing your test measured once. In the weeks after any pentest, a normal company will:
- ship new code, and with it new endpoints, new APIs, new parameters to fuzz;
- spin up a marketing microsite, a staging environment, a “quick” demo box - and forget it;
- renew or add TLS certificates, some on hosts nobody remembers owning;
- adopt a new SaaS tool that quietly publishes a subdomain;
- inherit a vulnerability that did not exist on test day, because the flaw was in a dependency and the advisory landed last Tuesday.
None of that is negligence. It is what a living company looks like. But every one of those events is a change to the exact surface the pentest certified as “tested.” The photograph is still hanging on the wall, and it is quietly going out of date the moment it is printed.
The finding that hurts is the one that appears three weeks later
The vulnerabilities that cause real incidents are rarely the ones sitting in an annual report waiting patiently to be fixed. They are the ones that open after the test:
A pre-auth remote code execution bug gets published for the web framework you use. Within hours it is being sprayed across the internet by automated scanners - the same background radiation that hits every public endpoint, including ours. Your pentest, three months old, says nothing about it, because on test day the bug did not exist. Your next test is nine months away.
That is the window. Not a theoretical one - a measurable, calendar gap between “we were tested” and “we will be tested again,” during which your surface changed and the threat landscape moved and nobody was watching the two of them collide.
Continuous is the film
Continuous attack-surface monitoring closes that gap by doing the boring thing relentlessly: watching. Our product, Perimetr, runs discovery and assessment against your external estate continuously, not annually. It notices the new subdomain the day it appears. It re-checks known assets against live exploit intelligence - CISA’s Known Exploited Vulnerabilities catalog, EPSS exploitation probabilities, OSV dependency advisories - so that when a bug that matters starts being exploited, the question “are we exposed to this?” has a same-day answer instead of a same-year one.
The economics that make this feasible are worth being honest about: AI agents do the discovery and assessment toil, continuously, on infrastructure we own. That is why continuous monitoring can cost SMB money instead of enterprise money. You are not paying a consultant to re-run a scan every week; you are paying for the judgment applied to what the scan finds - which brings us to the part that keeps continuous monitoring from becoming continuous noise.
Continuous does not mean automated-and-unaccountable
The obvious failure mode of “always-on scanning” is that it drowns you. A scanner pointed at your estate 24/7 will generate a thousand alerts a week, most of them false positives, duplicates, or theoretical severities nobody will ever exploit. That is not monitoring; that is a denial-of-service attack on your own attention.
So the machines find, but they do not get the last word. Every finding Perimetr surfaces is validated and signed by a named security professional before it reaches you. False positives die at that gate, not in your inbox. If it is in your report, a human vouched for it. Continuous discovery with a human sign-off is the combination that makes “always watching” survivable - you get signal, continuously, without the spam.
You still want the pentest, though
None of this means the point-in-time pentest is worthless. It is not, and we sell one precisely because it earns its place:
- Auditors and enterprise customers ask for one. A named, scoped, senior-led penetration test with an auditor-accepted report is often a hard requirement for ISO 27001, SOC 2, or a procurement checklist. Continuous monitoring does not replace that artefact.
- Depth. A focused engagement goes deeper on business logic, chained exploits, and assumed-breach scenarios than continuous discovery is designed to. The photograph is high-resolution for a reason.
- It’s the usual way in. Most clients start with a pentest, then bolt on continuous monitoring afterwards - because the finding that scared them was the one that showed up three weeks after the report was signed.
The honest model is not “continuous instead of point-in-time.” It is: the pentest is the photograph you need for the auditor; continuous monitoring is the film that runs the other 364 days. One tells you where you stood. The other tells you where you’re standing right now.
The buying question, reframed
If you take one thing from this, let it be a change in the question you ask.
The old question is “when is our next pentest?” It has an answer, it goes in a calendar, and it quietly assumes nothing important happens in the gaps.
The better question is “who is watching our attack surface between tests, and how fast would we know if something that matters opened up?”
If the honest answer is “nobody” and “at the next test,” you have found the gap. Closing it does not require throwing out the pentest, hiring a team, or paying enterprise prices. It requires someone - or something, with a human signing off - keeping the film rolling.
Curious what your external estate actually looks like right now - including the assets you’ve forgotten you own? A 30-minute scoping call will tell you your asset count and whether anything is currently on fire. No theatre, no pressure. See what’s exposed.
Get new posts by email
Security engineering, compliance without theatre, open-source threat intel. No tracking, no forwarding your address, unsubscribe in one click.